Re: New process of getting changes into the commitfest app - Mailing list pgsql-hackers

From Jelte Fennema-Nio
Subject Re: New process of getting changes into the commitfest app
Date
Msg-id CAGECzQTkBNc1TZWkZfdOaxZVN5e88heOjZjK5VUW_py7+Rq0Eg@mail.gmail.com
Whole thread Raw
In response to Re: New process of getting changes into the commitfest app  (Umar Hayat <postgresql.wizard@gmail.com>)
List pgsql-hackers
On Mon, 27 Jan 2025 at 05:38, Umar Hayat <postgresql.wizard@gmail.com> wrote:
> +1 in github you can enforce a minimum number of reviewers. IMO there
> should be a minimum of two reviewers and one of the reviewers should
> be from the security group/role.

In a perfect world I'd agree, but I don't think there are currently
enough people involved in the project to make two reviewers a
realistic option.

> Though primary risk would be
> introducing new vulnerable dependency but there is no bound to other
> kinds of exploitation. Also github vulnerability scan should be
> enabled by default.

Enabled that now on my Github mirror. I don't think it'll actually do
anything though. We don't pin exact python dependency versions,
because on prod we only use Python dependencies available in Debian
(which should resolve security issues).



pgsql-hackers by date:

Previous
From: Amit Kapila
Date:
Subject: Re: create subscription with (origin = none, copy_data = on)
Next
From: Jelte Fennema-Nio
Date:
Subject: Re: New process of getting changes into the commitfest app